Product
Liberu CRM versions 0.9.1 through 10.0.0 are vulnerable to privilege escalation via a broken access control flaw in the team invitation workflow, allowing users with pending invites to provision unauthorized administrator accounts.